Reference

How olxto Handles Your Personal Information

This Privacy Policy explains what data we collect when you use your olxto account, how we store it, and how we protect it — including information tied to your DANA, OVO, and GoPay wallet activity.

Account data protectionDANA, OVO, GoPay transaction privacyClear data retention termsYour right to request changesIndonesia-region scope
olxto How olxto Handles Your Personal Information
PRIVACY CONTACT PATHS

Reach Us About Your Privacy Rights

If you want to review, update, or request deletion of your personal data, our support team is available around the clock. You can reach us through live chat directly from your account dashboard, by email for written requests that need a formal response, or through our in-app help centre if you access olxto from your mobile device. We aim to respond to all data-related requests promptly.

Team online

Live Chat Support

Access live chat from your account dashboard at any time. This channel handles data queries, wallet-related privacy questions involving DANA, OVO, or GoPay, and account access concerns. Our team will confirm receipt and follow up within the same session where possible.

Email Request

Send a written data request to our support email address listed in your account settings. Use this for formal requests to access, correct, or delete your personal information. We process email requests in line with applicable local legal obligations and will confirm the outcome in writing.

In-App Help Centre

If you use olxto on your mobile device, tap the Help section inside the app to raise a privacy query directly. This path is convenient for quick questions about what data your wallet activity has generated or how your account information is stored on our system.

DATA HANDLING STANDARDS

How We Protect and Manage Your Account Data

Data security at olxto is built around the account itself — not just the login screen. From the moment you link your DANA, OVO, or GoPay wallet to your account, every transaction and session is handled with layered security controls. We apply SSL encryption across all data in transit, store sensitive account records on access-controlled servers, and review our data handling practices in line with evolving regional requirements. Here is a clear breakdown of our six core data management commitments.

Encrypted Data in Transit

Every piece of data that moves between your device and our platform — including your wallet credentials and deposit confirmations from DANA, OVO, or GoPay — travels through SSL-encrypted connections. This applies whether you access olxto via mobile browser or the app on your device.

Cookie and Session Tracking

We use session cookies to keep you logged into your account securely and to remember your preferences. Analytics cookies help us understand which account features you use most. You can manage cookie preferences through your browser settings; disabling certain cookies may affect how your account session functions.

Wallet Transaction Privacy

When you deposit or withdraw using DANA, OVO, or GoPay, we record the transaction reference, amount, and timestamp on our side. This record is used only for account reconciliation and dispute resolution. We do not store your full e-wallet PIN or authentication credentials — those remain with the respective wallet provider.

Account Security Verification

If we detect unusual login behaviour — such as a new device or a location change — your account may trigger an additional verification step before access is granted. This protects your account data even if your login credentials are compromised elsewhere. You can review active sessions from your account security settings.

Data Retention Policy

We retain your personal data for as long as your account remains active. If you close your account, we hold transactional records for the minimum period required by applicable legal obligations in your eligible region. After that period, your data is deleted or anonymised from our active systems.

Your Right to Request Changes

You have the right to ask us what personal data we hold, request a correction if something is wrong, or ask us to delete your account data where local law allows. Submit your request through live chat or email. We will confirm the action taken and the timeline, in writing, once your identity has been verified.

Common Questions About Our Privacy Policy

These questions reflect what account holders in Indonesia most often ask about how olxto manages their personal data, wallet transaction records, and their rights under this policy. If your question is not covered here, our live chat team can help you directly.

We collect the information you provide when registering — your name, contact details, and the payment method you choose, such as DANA, OVO, or GoPay. We also collect session data, device identifiers, and transactional records generated when you deposit or withdraw from your account wallet.

We do not sell your data. We share limited account information only with the payment processors needed to complete your wallet transactions — for example, the infrastructure behind DANA, OVO, or GoPay. No personal data is passed to advertisers or unrelated third parties.

Every deposit and withdrawal made through DANA, OVO, or GoPay is processed over SSL-encrypted connections. We record only the transaction reference, amount, and timestamp on our servers. Your wallet PIN and authentication credentials remain with your e-wallet provider — we never store those on our system.

Yes. Raise a data access request through live chat or email us using the address in your account settings. Once we verify your identity, we will provide a summary of the personal data we hold about your account. This right is subject to applicable local law in your eligible region.

Contact our support team via live chat or email with your request. For corrections, provide the accurate information you want us to update. For deletion, we will process your request after identity verification and notify you of the outcome and any legal retention obligations that apply.

When you close your account, we retain transactional records for the minimum period required under applicable legal obligations in your region. After that period ends, your personal data is deleted or anonymised from our active systems. We do not hold data longer than legally required.

We use session cookies to maintain your login and account preferences, and analytics cookies to understand how account features are used. You can manage or disable cookies through your browser settings. Note that disabling session cookies may affect your ability to stay logged in during your session.

If our system detects a login from a new device or an unexpected location, your account may require an additional verification step before access is granted. This is a security measure to protect your personal and payment data. You can review and manage active sessions from your account security settings.

This policy applies to all account interactions where local law permits, including players in Yogyakarta and Denpasar. Access to our services and the scope of data rights available to you depend on local law and the eligible regions applicable to your situation at the time of access.

When we make material changes to this policy, we will notify you through your registered account — either via an in-app message or an email to your account address. We recommend reviewing this page periodically. Continued use of your account after a policy update indicates your acknowledgment of the revised terms.